Maintainer Tokens, Not Package Names, Are the Weak Point

The weak point is the maintainer identity and its tokens. Once an attacker controls one publisher account, a trusted package update can become the delivery path, and stolen npm tokens can carry that compromise into other maintainers and unrelated packages. Socket says it tracked an active supply-chain attack that took over a maintainer account, pushed malware into keyv and cacheable, then spread through stolen npm tokens. Those packages sit deep in dependency trees and see tens of millions of weekly downloads, so the blast radius is much larger than the named packages. The risk now is fan-out. Patching a package does not end the problem if the publisher identity is still compromised or the stolen tokens are still valid.

Part of the PlainSec briefing for 2026-08-08

Every edition of this story: Maintainer Tokens, Not Package Names, Are the Weak Point

Sources